CVE-2026-44168
published 2026-06-12CVE-2026-44168: MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11…
PriorityP350high8CVSS 3.1
AVNACHPRHUINSCCHIHAH
EPSS
0.57%
43.1th percentile
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mariadb | mariadb | — | — |
| mariadb | mariadb | — | — |
| mariadb | mariadb | >= 10.11.1 < 10.11.17 | 10.11.17 |
| mariadb | mariadb | >= 10.6.1 < 10.6.26 | 10.6.26 |
| mariadb | mariadb | >= 11.4.1 < 11.4.11 | 11.4.11 |
| mariadb | mariadb | >= 11.8.1 < 11.8.7 | 11.8.7 |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb | server | — | — |
| mariadb_10.11 | mariadb | — | — |
| mariadb_11.8 | mariadb | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer
vendor_redhat·2026-06-12·CVSS 8.0
CVE-2026-44168 [HIGH] CWE-78 mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer
mariadb: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
A flaw was found in MariaDB. During a State Snapshot Transfer (SST), the donor node improperly validates parameters sent by a joiner node. This vulner
VulDB
MariaDB Server up to 12.3.1 joiner os command injection (GHSA-vwf7-w26c-9w5h / EUVD-2026-36514)
vuldb·2026-06-12·CVSS 8.0
CVE-2026-44168 [HIGH] MariaDB Server up to 12.3.1 joiner os command injection (GHSA-vwf7-w26c-9w5h / EUVD-2026-36514)
A vulnerability, which was classified as critical, was found in MariaDB Server up to 10.6.25/10.11.16/11.4.10/11.8.6/12.3.1. Impacted is an unknown function of the component joiner Handler. Such manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-44168. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44168 mariadb10.11: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer [fedora-all]
bugzilla·2026-06-30·CVSS 8.0
CVE-2026-44168 [HIGH] CVE-2026-44168 mariadb10.11: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer [fedora-all]
CVE-2026-44168 mariadb10.11: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the maria
Bugzilla
CVE-2026-44168 mariadb11.8: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer [fedora-all]
bugzilla·2026-06-30·CVSS 8.0
CVE-2026-44168 [HIGH] CVE-2026-44168 mariadb11.8: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer [fedora-all]
CVE-2026-44168 mariadb11.8: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariab
Bugzilla
CVE-2026-44168 mariadb: MariaDB: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer
bugzilla·2026-06-12·CVSS 8.0
CVE-2026-44168 [HIGH] CVE-2026-44168 mariadb: MariaDB: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer
CVE-2026-44168 mariadb: MariaDB: Arbitrary Code Execution via improper parameter validation during State Snapshot Transfer
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were properly validated which could allow a malicious joiner to execute arbitrary shell commands on the donor side via the mariabackup SST method. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.
https://github.com/MariaDB/server/security/advisories/GHSA-vwf7-w26c-9w5hhttps://jira.mariadb.org/browse/MDEV-39413https://access.redhat.com/errata/RHSA-2026:25143https://access.redhat.com/errata/RHSA-2026:25145https://access.redhat.com/errata/RHSA-2026:33093https://access.redhat.com/errata/RHSA-2026:33412https://access.redhat.com/errata/RHSA-2026:33464https://access.redhat.com/errata/RHSA-2026:33481https://access.redhat.com/errata/RHSA-2026:33482https://access.redhat.com/security/cve/CVE-2026-44168https://bugzilla.redhat.com/show_bug.cgi?id=2488450https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44168.json
2026-06-12
Published